Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)
Key Takeaways Elastic has addressed a critical data interception vulnerability in Kibana, tracked as CVE-2026-102406, with a CVSS score of 8.8. The flaw allows delegated Fleet users to hijack data...
Key Takeaways
- Elastic has addressed a critical data interception vulnerability in Kibana, tracked as CVE-2026-102406, with a CVSS score of 8.8.
- The flaw allows delegated Fleet users to hijack data streams and intercept information from other users or teams within the same Kibana deployment.
- Affected Kibana versions range from 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3.
- Patches are available in versions 8.19.22, 9.4.7, and 9.5.4, along with fixes for several other high and medium-severity issues across Elastic products.
Elastic has released a series of security updates, patching a total of 14 vulnerabilities across its product suite, including Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a critical flaw in Kibana (CVE-2026-102406), scoring 8.8 on the CVSS scale, stands out for its potential to allow unauthorized data interception.
Table Of Content
Kibana Flaw Enables Data Stream Hijacking
The high-severity Kibana vulnerability, identified as CVE-2026-102406, stems from an oversight in Fleet’s package installation process. Specifically, the system failed to adequately verify ownership before applying integration settings from uploaded packages to existing data streams. This critical weakness could be exploited by an attacker with permissions to install custom Fleet packages.
Such an attacker could claim a data stream identifier already in use by another user or team within the same Kibana deployment—referred to as a “tenant”—without needing direct administrative privileges within Elasticsearch. Once control of the data stream was usurped, Fleet would apply the attacker’s custom index and ingest-pipeline settings. This action would reroute newly ingested information through infrastructure controlled by the attacker, exposing sensitive data to unauthorized access, modification, and preventing it from reaching its legitimate destination.
Elastic emphasizes that the interception could persist even after the malicious package is removed. Therefore, administrators must go beyond simply removing the package and thoroughly inspect and repair any affected infrastructure to ensure complete remediation.
Affected Versions and Patches
The critical Kibana flaw impacts versions 8.14.0 through 8.19.21, 9.0.0 through 9.4.6, and 9.5.0 through 9.5.3. Both self-managed and Elastic Cloud Hosted installations are vulnerable if delegated users have the ability to upload custom integration packages. Corrective patches have been released in versions 8.19.22, 9.4.7, and 9.5.4.
Additional High-Severity Vulnerabilities Addressed
Beyond the Kibana data interception flaw, Elastic also patched CVE-2026-103009, another high-severity vulnerability with a CVSS score of 7.1. This issue affects cross-cluster search when utilizing Remote Cluster Security 2.0. A specially crafted request could bypass authorization for an allowed index, granting access to a different, unauthorized index, thereby exposing documents, mappings, and metadata. This particular vulnerability requires access via the remote cluster transport interface and cannot be exploited through the REST API.
Elasticsearch and Elastic Endpoint Updates
Elasticsearch received fixes for two denial-of-service (DoS) vulnerabilities. CVE-2026-103008, with a CVSS score of 6.5, allows an authenticated user with index read access to trigger excessive recursion through scripted geometry, leading to node termination. Similarly, CVE-2026-102404, also scoring 6.5, could be exploited using crafted ES|QL queries to exhaust memory, causing repeated disruptions to cluster availability. Both Elasticsearch DoS issues are resolved in versions 8.19.23, 9.4.8, and 9.5.5.
Elastic Endpoint also received an update for CVE-2026-102413, rated 6.2. This vulnerability could cause repeated crashes when processing specially crafted filenames under certain Windows locales, including Chinese, Japanese, and Korean. Such crashes could compromise or disable malware prevention and behavioral detection capabilities.
Elastic had already remediated the Kibana flaw in its Cloud Serverless offering prior to public disclosure.
What You Should Do
- Immediately apply the latest security patches to your Elastic deployments. For Kibana, upgrade to versions 8.19.22, 9.4.7, or 9.5.4. For Elasticsearch, upgrade to 8.19.23, 9.4.8, or 9.5.5.
- Review the official Elastic security advisories and upgrade notes for detailed instructions and potential post-upgrade steps.
- Until Kibana can be patched, restrict the ability to upload custom Fleet integration packages to only full superusers.
- Administrators should meticulously examine all uploaded Fleet packages for any indication of reused datasets or unexpected modifications to existing ingest pipelines.
- If the Kibana data interception flaw (CVE-2026-102406) is suspected to have been exploited, conduct a thorough forensic investigation of affected infrastructure to ensure complete remediation beyond just package removal.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.